FortiExtender
FortiExtender offers wireless connectivity for nearly any operational network.
wleo
Staff
Staff
Article Id 227390

Description

 

This article describes Virtual Router Redundancy Protocol (VRRP) service and DNS service between FortiGate and FortiExtender.

After integration between FortiGate and FortiExtender, VRRP service enables Internet service continuance, either network service fails on FortiGate, which automatically triggers the network service on FortiExtender or network service fails on FortiExtender, which automatically triggers the network service on FortiGate. 

While VRRP is on service between FortiGate and FortiExtender, DNS service is also automatically enabled when FortiGate is on Primary state or FortiExtender is on Master mode. 

 

Scope

 

FortiGate and FortiExtender integration with VRRP service and DNS service. 

 

Solution

 

1) On FortiExtender, configure interface for data channel to prepare integration with FortiGate.

On the interface, also enable VRRP with vrrp ip address and its parameters, example as the below snapshot  (disable or remove DHCP service, since not allow to enable VRRP and DHCP service on one same interface)

 

wleo_0-1666294188304.png

 

2) On FortiExtender, configure Control Channel to prepare integration with FortiGate. Example to use port4 to set up Control Channel with FortiGate.

 

wleo_1-1666294292520.png

 

3) On FortiExtender, go to Settings - > Management to configure the following parameter:

management type as auto or FortiGate.

Discovery Type as static or broadcast.

Discovery Interface requires the interface of Control Channel interface; In this scenario, the interface is port4 with its ip address as 192.168.4.1.

 

wleo_2-1666294515167.png

 

4) On FortiExtender, go to Setting - > Management to configure FortiGate Backup, as the below snapshot:

enable VRRP for the interface, in this scenario it is LAN interface.

 

wleo_3-1666294699149.png

 

5) On FortiGate, configure Data Channel for the interface, which requires the same subnet on FortiExtender Data Channel interface.

Example in this scenario, using port1 on FortiGate as Data Channel, which aligns to the LAN interface on FortiExtender.

 

wleo_4-1666294906329.png

 

6) On FortiGate, to configure Control Channel which aligns to the Control Channel interface on FortiExtender.

In this scenario, port 2 is configured as Control Channel.

 

wleo_5-1666295039231.png

 

7) On FortiGate, Create on FortiExtender WAN Extension.

 

wleo_6-1666295143252.png

 

8) Choose the FortiExtender WAN interface to connect FortiExtender.

 

wleo_0-1666296004061.png

 

9) On FortiGate, configure VRRP service for the interface; In this scenario, it is port 1

VRRP ip address must be the same as the VRRP ip address on FortiExtender VRRP interface.

 

wleo_1-1666296097917.png

 

10) On FortiGate, Configure DNS service for the VRRP interface. In this scenario, it is port1.

 

wleo_2-1666296207479.png

 

11) On FortiExtender, Configure DNS service for the VRRP interface. In this scenario, it is LAN interface.

 

wleo_3-1666296325360.png

 

12) On Client, configure DNS service; The DNS server must be the IP address of VRRP service. In this scenario, the DNS IP must be: 192.168.200.100.

 

wleo_4-1666296496092.png

 

wleo_5-1666296553002.png

 

13) When FortiGate VRRP interface is up, check VRRP status on FortiGate

In this scenario, make FortiGate port1 is up; Check VRRP status

 

On FortiGate: 

 

wleo_6-1666296708100.png

 

On FortiExtender:

 

wleo_7-1666296738079.png

 

14) On Client, ping website to get DNS service from FortiGate

 

wleo_8-1666296885359.png

 

15) On FortiGate, turn down VRRP interface; or Reboot FortiGate to disconnect network service from FortiGate.

On FortiGate, check VRRP status:

 

wleo_9-1666297023007.png

 

On FortiExtender, check VRRP status:

 

wleo_10-1666297077123.png

 

16) On Client, ping website, and can get network service and DNS service from FortiExtender:

Using one domain, which is in FortiExtender DNS shadow or public database, which indicates DNS on FortiExtender is serving the client:

 

wleo_11-1666297268657.png

 

17) Turn up the FortiGate port 1 interface, following the step 16:

 

On FortiGate:

 

wleo_12-1666297391182.png

 

On FortiExtender:

 

wleo_13-1666297426265.png

 

18) On Client, lookup the domain name which is in FortiExtender DNS database. DNS returns no naming resolution since FortiExtender is on backup state but FortiGate is taking DNS service.

 

wleo_14-1666297519349.png

Contributors